New Stealer Combines Credential Theft, HVNC, SOCKS5 Proxy, and AI Victim Scoring
ID: 924e671c-b1cd-52d9-9efa-fdacf5dfba2f
STIX ID: report--924e671c-b1cd-52d9-9efa-fdacf5dfba2f
Feed Name: Cyber Press
**Executive summary:** Dolphin X is a commercial Windows infostealer and RAT advertised by an actor called "Kontraktnik" that targets developers and general users to harvest browser credentials, cryptocurrency wallets and extensions, password managers, .env files, SSH keys, cloud access tokens, and developer CLI credentials; it supports HVNC, SOCKS5 proxying, process injection, multiple persistence and evasion techniques, server-side remote builds with mutation to evade signatures, and an AI Profiler to rank high-value victims. Varonis analyzed the operator panel and network traffic, mapped behaviors to ATT&CK techniques (e.g., T1560, T1555), and recommended behavior-based detection, while noting many agent features remain vendor-claimed rather than independently validated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
